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CLAIMS 

We claim as our invention: 

1 . A program product comprising: 

a computer useable medium having computer readable program code stored therein, 
the computer readable program code in said program product being effective when executing 
to: 

determine the location of a computer which has a storage device 
adapted to store various data files and assume a selected location in the 
computer based on the determined location; 

tag files to be stored in the storage device according to the selected 
location; and 

implement a filter which (a) passes files tagged according to the 
selected location and removes the tags applied by the code which is effective 
to tag and which (b) blocks files not tagged according to the selected location. 

2. The product of Claim 1 wherein the code which is effective to tag files is code which 
appends characters to the data file name. 

3. The product of Claim 1 wherein the location is determined by assessing a system 
resource. 

4. The product of Claim 3 wherein the system resource is selected from the group 
consisting of network settings and printer settings. 
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5. A program product comprising: 

a computer useable medium having computer readable program code stored therein, 
the computer readable program code in said program product being effective when executing 
to: 

determine the location of a computer which has a storage device 
adapted to store various data files and assume a selected location in the 
computer based on the determined location; 

tag files to be stored in the storage device according to the selected 
location wherein the contents of the tagged files are stored in an encrypted 
format on the storage device; and 

implement a filter which (a) passes files tagged according to the 
selected location and removes the tags applied by the code which is effective 
to tag files and decrypts the contents of tagged files which have been stored in 
an encrypted format on the storage device and which (b) blocks files not tagged 
according to the selected location; 
wherein, when at least one application is executed in the computer, a change in the selected 
location based on a newly determined location does not require termination of the at least one 
application. 

6. The product of Claim 5 wherein the code which implements the filter further passes files 
tagged as universal irrespective of the selected location and thereby overrides the filter action 
(b) which otherwise blocks files not tagged according to the selected location. 

7. The product of Claim 5 wherein a call to a cryptographic processor is made in a 
selected one of the location determination performed by the code which determines, the 
encryption performed by the code which implements the filter, and the decryption performed 
the code which implements the filter. 
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8. The product of Claim 7 wherein the cryptographic processor called is a trusted platform 
module. 

9. The product of Claim 5 wherein the code which is effective to tag files is code which 
appends characters to the data file name. 

10. The product of Claim 5 wherein the location is determined by assessing a system 
resource. 

1 1 . The product of Claim 10 wherein the system resource is selected from the group 
consisting of network settings and printer settings. 

1 2. A method comprising the steps of: 

determining the location of a computer which has a storage device adapted to store 
various data files and assuming a selected location in the computer based on the determined 
location; 

tagging files to be stored in the storage device according to the selected location; and 
implementing a filter which (a) passes files tagged according to the selected location 

and removes the tagging applied in said tagging step and which (b) blocks files not tagged 

according to the selected location. 

1 3. The method of Claim 1 2 wherein said tagging is one which appends characters to the 
data file name. 

1 4. The method of Claim 1 2 wherein the location of said determining step is determined 
by assessing a system resource. 
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15. The method of Claim 14 wherein the system resource is selected from the group 
consisting of network settings and printer settings. 

1 6. A method comprising the steps of: 

determining the physical location of a computer which has a storage device adapted 
to store various data files and assuming a selected location in the computer based on said 
determination; 

tagging files to be stored in the storage device according to the selected location 
wherein the contents of the tagged files are stored in an encrypted format on the storage 
device; and 

implementing a filter which (a) passes files tagged according to the selected location 
and removes the tagging applied in said tagging step and decrypts the contents of tagged 
files which have been stored in an encrypted format on the storage device and which (b) 
blocks files not tagged according to the selected location; 

wherein, when at least one application is running in the computer, a change in the 
selected location based on newly determined location does not require termination of the at 
least one application. 

17. The method of Claim 16 wherein the filter implemented in said implementing step 
further passes files tagged as universal irrespective of the selected location and thereby 
overrides the filter action (b) which otherwise blocks files not tagged according to the selected 
location. 

1 8. The method of Claim 1 6 wherein a cryptographic processor is utilized in a selected 
one of the location determination in said determining step, the encryption performed in said 
filter implementing step, and the decryption performed in said filter implementing step. 
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1 9. The method of Claim 1 8 wherein the cryptographic processor is a trusted platform 
module. 

20. The method of Claim 16 wherein the tagging in said tagging step is one which 
appends characters to the data file name. 

21 . The method of Claim 1 6 wherein the location of said determining step is determined 
by assessing a system resource. 

22. The method of Claim 21 wherein the system resource is selected from the group 
consisting of network settings and printer settings. 

23. Apparatus comprising: 

a location switch which determines the physical location of a computer having a 
storage device capable of storing various data files, the location switch indicating a selected 
location based on the determined location; 

a tagger which is coupled to said location switch and which tags files to be stored in 
the storage device by modifying the names of the files according to the selected location as 
indicated by said location switch; and 

a filter which is coupled to said location switch and which (a) passes files tagged 
according to the selected location by restoring each file name to the name existing prior to the 
modification performed by said tagger and which (b) blocks files not tagged according to the 
selected location. 

24. Apparatus of Claim 23 wherein the data file name modification is one which appends 
characters to the data file name. 
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25. Apparatus of Claim 23 wherein the location is determined by assessing a system 
resource. 

26. Apparatus of Claim 25 wherein the system resource is selected from the group 
consisting of network settings and printer settings. 

27. Apparatus comprising: 

a location selector which determines the location of a computer and which indicates 
a selected location based on the determined location, wherein a storage device included in 
the computer is capable of storing various data files; 

a tagger which is coupled to said location selector and which tags files to be stored in 
the storage device by modifying the names of the files according to the selected location as 
indicated by said location selector and which stores the contents of the tagged files in an 
encrypted format on the storage device; and 

a filter which is coupled to said location selector and which (a) passes files tagged 
according to the selected location by restoring each file name to the name existing prior to the 
modification performed by said tagger and by decrypting the contents of tagged files which 
have been stored in an encrypted format on the storage device and which (b) blocks files not 
tagged according to the selected location; 

wherein, when at least one application is running in the computer, a change in the 
selected location based on a newly determined location does not require termination of the 
at least one application. 

28. Apparatus of Claim 27 wherein said filter further passes files tagged as universal 
irrespective of the selected location, thereby overriding the blocking (b) of files not tagged 
according to the selected location. 
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29. Apparatus of Claim 27 wherein a cryptographic processor is utilized in a selected one 
of the location determination performed by said location selector, the encryption performed 
by said filter, and the decryption performed by said filter. 

30. Apparatus of Claim 29 wherein the cryptographic processor is a trusted platform 
module. 

31 . Apparatus of Claim 27 wherein the location is determined by assessing a system 
resource. 

32. Apparatus of Claim 31 wherein the system resource is selected from the group 
consisting of network settings and printer settings. 
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